FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant scoping and retrieve other clients’ data. Details
In ServiceTransaction::getSearchQuery() and Order\Service::getSearchQuery(), OR-based search/action filters were appended without grouping, allowing SQL operator precedence to evaluate OR clauses independently of the enforced client_id constraint. Crafted requests could therefore return records and metadata belonging to other clients, including identifiers, amounts, status, timestamps, and related fields. This issue was fixed in version 0.8.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
23 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 21:16
Updated : 2026-06-23 21:16
NVD link : CVE-2026-23513
Mitre link : CVE-2026-23513
CVE.ORG link : CVE-2026-23513
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
